Implement DPDP & privacy compliance across customer and vendor journeys - via a single platform

Privacy-first companies have already started using Consentin

Data catalogue assetImage of productImage of product

DPDP Rules are here - comply fast with Consentin

Collect and manage DPDP-compliant consent across customer journeys

Collect consent (and cookies) in 22 Indian languages
2-click consent collection that minimizes drop offs
Sync your consents across business and 3rd party databases with webhooks, Consent Check API and Reports
Image of productImage of product
Image of productImage of product

Manage and respond to rights requests

Allow customers to update or withdraw consents easily with Consentin Privacy Centre
Send automated deletion instructions to internal and third party systems when consent is withdrawn

Use

to identify and

classify personal data

Accurately detect personal data across structured and unstructured data systems - including SQL databases, CRMs, cloud storage platforms, and internal servers.
Map your data and systems in a detailed data map
Use our detailed data lineage to get complete visibility on your data flows and identify downstream risks
Image of productImage of product
Image of productImage of product

Automate third party risk assessments and breach notifications

Assess security, data handling, and compliance capabilities of external partners
Get detailed reports on privacy risks with 3rd party vendors
Automatically send breach notices to affected users within DPDP-mandated timelines

Consentin is built for Indian businesses that want end-to-end DPDP compliance at scale

Built by Leegality

India's leading Document Infrastructure platform, established in 2016 and built by lawyers with deep RegTech experience. 600+ enterprise implementations.

Proven at scale

15 crore+ signature consents processed and 1,000 TB of data managed through the Leegality Document Execution Platform.

30+ ongoing DPDP implementations

5,000 TB of data under discovery via Consentin Lens, across 50+ unique databases.

Recognised and certified

SOC 2 compliant; ISO 27001:2022, 27017, 27018 and 22301 certified. Part of the judges’ panel for NeGD’s “Code for Consent” Challenge.

Easy deployment and integration

Integrate across CRM, LOS, website, app and IVR with minimal IT involvement.

Criteria

Recurring Fee
Consent Collect Cost
Consent Storage Cost
Consent Check
Data Discovery

Consentin (SaaS/Cloud)

Annual/Quarterly Flat Fee
Included in Annual/Quarterly Fee
₹0
Included in Annual/Quarterly Fee
Data Discovery is just on On Prem

Consentin (On Prem)

Annual Fee basis No. of Profiles
₹0
₹0
₹0
₹ (no. of connectors + no. of endpoints)

We have an irresistible starter offer for you

3000 DPDP-compliant consent collections/month — ₹0 (forever)

With our Starter Pack, you can collect 3,000 consents per month at ₹0—forever.

If your volumes are ≤ 3,000 / month, run DPDP end-to-end at no cost.

If your volumes are > 3,000 / month, use this to run a free live pilot before you buy.

Sign up for a DPDP Demo to start using Consentin

In 35 minutes, we will:
Give you a 10-minute breakdown of how the DPDP Act changes your existing flow
Give you a 25 minute demo of the Consentin DPDP Compliance Platform - and how to set it up
Answer any of your questions
Give you a free Consentin account to avail the offer
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Frequently asked questions

What is a Consent Manager?
+

Under the DPDP Act, a Consent Manager is a person registered with the Data Protection Board who acts as a single point of contact to enable a user to give, manage, review, and withdraw their consent through an accessible, transparent, and interoperable platform.

Registration for Consent Managers opens on 13th November 2026. There are no registered Consent Managers in India yet.

What is a Data Processor?
+

A Data Processor is an entity that processes data on behalf of a Data Fiduciary, acting under its instructions. It does not determine why and how the data is processed.

When do I need to take user consent?
+

Under the DPDP Act, you must take user consent when processing digital personal data or physical personal data digitized subsequently, unless the processing falls under specific exemptions provided by the Act. Key scenarios requiring user consent include:

  • Collecting Personal Data: when collecting personal data for any purpose.
  • Sharing Data with Third Parties: before sharing user data with external entities.
  • Using Data for New Purposes: if the purpose of processing changes from what was initially communicated.
  • Retention Beyond Purpose: if data needs to be retained for reasons other than the original purpose of collection.
Is the DPDP Act in force?
+

Yes, the DPDP Rules were notified on 13th November 2025, bringing the DPDP Act into force. The Rules introduce different timelines for different provisions.

Data Fiduciaries have been granted 18 months to comply with the Act and the Rules. This window ends on 13th May 2027.

What is the penalty for violating the DPDP Act?
+

Penalties under the DPDP Act can go up to ₹250 crore per violation.

To know more about penalties for different DPDP violations, see our blog.

What is a DPDP compliance platform?
+

A DPDP compliance platform is software that helps a business manage its obligations under the DPDP Act, including data discovery, data mapping, collecting consent, sending notices, handling data requests, and managing retention and deletion, all in one place.

What to do in case of a data breach under the DPDP Act?
+

A data breach is any unauthorized access, disclosure, alteration, or loss of personal data that puts its safety at risk.

If a breach happens, the Data Fiduciary must inform the Data Protection Board and each affected Data Principal. The Rules require this without delay, followed by a detailed report to the Board within 72 hours. To know more about breach notification under the DPDP Act, see our blog.

What's the difference between GDPR and DPDP?
+

There are several key differences:

  • Legal basis: GDPR allows six lawful bases for processing data; DPDP allows only two: consent and certain legitimate uses.
  • Penalties: GDPR fines are a percentage of global turnover; DPDP fines are fixed rupee amounts, capped at ₹250 crore per instance.
  • Officer requirement: GDPR mandates a Data Protection Officer for most processors; DPDP doesn't require one for every business.

That's why a GDPR-compliant platform may not be the right choice if you're looking for DPDP compliance. You need a platform built specifically for it.

Compliance Deadline:

0 weeks away